Skip to main content

How do permissions work in Insights?

Updated over a week ago

Insights permissions are simple by design—users either have access or they don’t.

There are no granular, report-level permissions. Instead, access is controlled through a small set of firm permissions that determine what users can see and do in Insights.


Required Plan, License, and Permissions

To use Insights, users must be granted Access to Insights.


Additional permissions determine whether they can create, share, or build reports using admin-level data.


Why this matters

Understanding how Insights permissions work helps firms:

  • Safely share reports without overcomplicating access controls

  • Know when sensitive data (like salary information) may be visible

  • Assign the right permissions to the right team members—without surprises


Table of Contents


How Insights Access Works

Insights does not support role-based or object-level permissions.

  • Users either have access to Insights or they do not

  • There are no restrictions by report, dashboard, or dataset once access is granted

The only Insights-specific permissions you can control are:

  • Access to Insights

  • Ability to Create/Share Answers


Creating and Sharing Answers

Users with the Ability to Create/Share Answers permission can:

  • Build new Answers (reports)

  • Share Answers with other users who have access to Insights

Users without this permission can still:

  • View Answers that have been shared with them

  • Interact with report data (filter, explore, download, etc.)


Admin-Level Access and Admin Data Sources

Only admin-level users can create reports using Admin Data Sources in Insights.

However, “admin-level” in Insights does not mean the user must be a Canopy Admin.

A user is considered admin-level for Insights if they have this permission:

  • Team Member Salary | View and edit team member salary and hourly rate

With this permission:

  • The user can access Admin Data Sources in Insights

  • This applies even if they are not an Admin in Canopy


Salary Data Visibility

Important to know:

  • Any report built using an Admin Data Source includes salary information

  • If that report is shared with a non-admin user:

    • The report is fully viewable

    • Salary data is not masked or restricted

    • This applies regardless of the user’s other Canopy permissions

Best practice:
Users with access to Admin Data Sources should be intentional about who they share reports with, since salary data is always fully visible to report viewers.


Canned Dashboards and Admin Data

Most pre-built (canned) Canopy dashboards:

  • Do not use Admin Data Sources

  • Are visible to all users with access to Insights

If a canned dashboard does use an Admin Data Source:

  • It is only visible to admin-level users (as defined above)


Summary

  • Insights permissions are intentionally simple—no granular controls

  • Users either have access to Insights or they don’t

  • Only two permissions apply:

    • Access to Insights

    • Ability to Create/Share Answers

  • Admin Data Sources are tied to salary permissions, not Canopy admin status

  • Any shared report built on Admin Data Sources exposes all included data


Need help?

Need help deciding who should have admin-level access in Insights?


Contact Support or ask Penny, our AI support bot, for guidance.

Did this answer your question?